<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>伪造ajax</title>
</head>
<!--点击提交会在inframe里加载我们写入url中的地址, 使用js实现, 并没有重新加载整个html,
    所以说是伪造的ajax-->
<body>
<script type="text/javascript">
    window.onload = function f(){
        var myDate = new Date();
        document.getElementById('currentTime').innerText = myDate.getTime();
    }
    function loadPage(){
        var targetURL = document.getElementById('url').value;
        console.log(targetURL);
        document.getElementById('iframePosision').src = targetURL;
    }
</script>

<div>
    <p>
        请输入要加载的地址:<span id="currentTime"></span>
    </p>
    <p>
        <input type="text" id="url" value="">
        <input type="button" value="提交" onclick="loadPage()">
    </p>
</div>
<div>
    <h3>
        加载页面的位置
    </h3>
    <iframe style="width: 100%;height: 500px" id="iframePosision"></iframe>
</div>

</body>
</html>